CVE-2026-83461
moderateUnauthenticated Data-Access and Partial DoS in Oracle EBS Mobile Application Server
CVE-2026-83461 is a vulnerability in the MWA Terminal Server component of the Oracle Mobile Application Server within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is remotely exploitable by an unauthenticated attacker who has network access to the service over TCP, requiring no privileges or user interaction. A successful attack lets the attacker compromise the Mobile Application Server, gaining unauthorized access to critical data or to all data the server can reach, and the ability to cause a partial denial of service. The flaw carries a CVSS 3.1 base score of 8.2 (high), driven by high confidentiality impact and low availability impact, with no integrity impact. It is not listed in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so no active exploitation has been observed.
What to do: Apply the Oracle Critical Patch Update that remediates this flaw on any E-Business Suite 12.2.3-12.2.15 environment running the MWA Terminal Server. Restrict TCP access to the MWA service to trusted warehouse/mobile-device networks via firewall rules, and do not expose it to the internet. Review MWA server logs for unexplained unauthenticated connections or data access and performance degradation consistent with attempted exploitation.
| Oracle E-Business Suite Mobile Application Server (MWA Terminal Server) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Mobile Application Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Mobile Application Server. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.